Karka

Free course

ISO 31000 — Enterprise Risk Management (Awareness)

Awareness of enterprise risk management: how risk is identified, assessed, treated and monitored, and how to contribute to it credibly.

What this course does not do

Awareness only. This is not a certification and confers no professional risk qualification. It also does not make your organisation certified against any standard; ISO 31000 is guidance rather than a certifiable requirements standard, and organisational certification generally comes from an accredited certification body after audit of a certifiable standard.

AwarenessBeginnerISO Compliance
6 modules 35 lessons 3 enrolled ~5h of material

First three lessons free. Full access with Founding Annual Access, ₹3,999 for your first year.

ISO 31000 — Enterprise Risk Management (Awareness)

By the end

What you'll build

  • Write a risk statement with a clear cause, event and consequence
  • Analyse a risk in terms of likelihood and consequence and explain the reasoning
  • Choose among avoid, reduce, share, retain and explain the trade-off
  • Identify a risk owner and the specific action that changes the risk level
  • Recognise common biases that distort risk estimates in group discussions
  • Challenge a risk rating constructively using evidence rather than instinct

Curriculum

What's inside

6 modules · 35 lessons

  1. 01

    Risk in plain terms

    6 lessons
    • Writing a risk statement with cause, event and consequence
    • Risk, issue, hazard and uncertainty distinguished
    • Upside risk and why opportunity belongs here
    • Principles that make risk management useful
    • Risk management as guidance, not a certifiable checklist
    • + 1 more lesson
  2. 02

    Context and identification

    6 lessons
    • Establishing context before you start listing risks
    • Internal and external context in practice
    • Techniques for identifying risks in a workshop
    • Emerging risk and weak signals
    • Avoiding a register full of the same risk five times
    • + 1 more lesson
  3. 03

    Analysis and evaluation

    6 lessons
    • Rating likelihood and consequence without pretending to precision
    • Qualitative and quantitative approaches
    • Risk criteria, matrices and their weaknesses
    • Cognitive biases in group risk estimates
    • Aggregating risk across a portfolio
    • + 1 more lesson
  4. 04

    Treatment and ownership

    6 lessons
    • Choosing a treatment that actually changes the risk
    • Avoid, reduce, share, retain: real trade-offs
    • Controls and their assumed effectiveness
    • Assigning ownership that carries authority
    • Residual risk and formal acceptance
    • + 1 more lesson
  5. 05

    Monitoring and communication

    6 lessons
    • Keeping a risk register alive instead of archived
    • Indicators that give early warning
    • Reporting risk to leadership without alarmism
    • Reviewing risks after an incident or a change
    • Embedding risk thinking into everyday decisions
    • + 1 more lesson
  6. 06

    Practice and check

    5 lessons
    • Risk vocabulary that gets mixed upmatch pairs
    • Getting a new risk onto the register properlysequence order
    • Say it the way the standard says itfill blank
    • The workshop that wants to write cyber risk highscenario
    • Course quizquiz

The shape of it

How this course works

Short lessons

35 lessons across 6 modules, each small enough to finish in one sitting.

Practice as you go

Every lesson ends with a small space for what you noticed — the doing is the learning.

Progress you can see

Your progress is saved lesson by lesson, ready whenever you come back.

Ready when you are.

Make an account and this course opens up — your progress is saved from the very first lesson.